Lucene search

K
cvelistJenkinsCVELIST:CVE-2023-24450
HistoryJan 24, 2023 - 12:00 a.m.

CVE-2023-24450

2023-01-2400:00:00
jenkins
www.cve.org
6
cve-2023-24450
jenkins
passwords
unencrypted
config.xml
extended read permission
jenkins controller
file system

EPSS

0.001

Percentile

29.1%

Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

CNA Affected

[
  {
    "product": "Jenkins view-cloner Plugin",
    "vendor": "Jenkins Project",
    "versions": [
      {
        "lessThanOrEqual": "1.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "unknown",
        "version": "next of 1.1",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.001

Percentile

29.1%

Related for CVELIST:CVE-2023-24450